Quantum Kolmogorov Complexity and Bounded Quantum Memory 



Takayuki Miyadera 
Research Center for Information Security (RCIS), 
National Institute of Advanced Industrial Science and Technology (AIST). 
Daibiru building 1003, Sotokanda, 
Chiyoda-ku, Tokyo, 101-0021, Japan. 
(E-mail: miyadera-takay uki@aist.go.jp) 
(Dated: February 9, 2011) 

In this study, the effect of bounded quantum memory in a primitive information protocol has been 
examined using the quantum Kolmogorov complexity as a measure of information. We employed 
a toy two-party protocol in which Bob by using a bounded quantum memory and an unbounded 
classical memory estimates a message that was encoded in qubits by Alice in one of the bases X or 
Z. Our theorem gave a nontrivial effect of the memory boundedness. In addition, a generalization 
of the uncertainty principle in the presence of quantum memory has been obtained. 

PACS numbers: 03.67.Lx, 03.65.Ta, 03.67.Dd 

I. INTRODUCTION 

Various ideas have been put forth and experiments have been conducted to construct a large and stable quantum 
memory. This is definitely the most important factor for achieving quantum information processing devices. However, 
despite the efforts expended thus far, it is difficult to imagine that any ultimate method will be proposed that enables 
the construction of an arbitrarily large quantum memory. 

This pessimistic view is not as disappointing as it may seem. Let us consider a two-party cryptographic protocol 
called oblivious transfer [lj], in which Alice sends a bit to Bob by executing a protocol in such a manner that Bob 
receives it correctly with probability 1/2 and nothing otherwise, but Alice cannot learn whether her bit was received. 
While the oblivious transfer could be a strong cryptographic primitive when realized, its secure realization without 
considering any assumptions is impossible even if one uses quantum communication 0, ||. Several studies have 
been conducted to investigate physical assumptions yielding the secure implementation of this protocol using classical 
communication. The first assumption is the boundedness of computation power, which is the most traditional approach 
based on a mathematically unproven computational complexity problem [lj. This approach implicitly contains a 
physical assumption: it assumes the processing speed of existing computers. The second assumption involves the 
imperfection of a communication channel. It has been demonstrated in various noise models that secure oblivious 
transfer is achievable 0,0]. The third assumption, which is related to the present study, is the boundedness of memory 
size. It has been shown that the protocol may be securely implemented if the size of an adversary's (classical) memory 
is restricted [f| . Although this result is interesting in theory, the assumption is not entirely valid because it is not too 
difficult to construct large classical memories with current technology. Recently, important work based on bounded 
quantum memory has been completed. In Q, Damgaard et al. have shown that the oblivious transfer becomes 
information-theoretically secure under the assumption that the size of the adversary's quantum memory is bounded. 
As mentioned earlier, the assumption of bounded quantum memory is more reasonable than that of bounded classical 
memory. In fact, the latest technology enables the stability of only a few qubits of memory. 

The protocol runs as follows. Alice encodes a random N bit sequence to a quantum state of N qubits in X or 
Z basis. She sends the qubits to Bob. Bob selects X or Z and measures the qubits with respect to the selected 
basis. After Alice announces the basis used for encoding, Bob knows whether his selection of the basis is correct. The 
privacy amplification phase causes the players to agree on a bit in the case that the basis is correct, otherwise the 
protocol makes Bob completely ignorant of the bit obtained by Alice. Alice can send Bob an arbitrary bit by XORing 
with her obtained bit. As intended, this method works as an oblivious channel. To demonstrate the security, assume 
that one of the players, Bob, is dishonest. If Bob has a quantum memory of size larger than N, he may not follow 
the protocol but may keep the quantum state and measure it with respect to the disclosed basis. This procedure 
provides the full information of an encoded sequence to Bob; thus the protocol fails. Further, imagine a case in which 
dishonest Bob's quantum memory is bounded. Since he cannot keep the entire quantum state, he has to irreversibly 
convert a part of the quantum state to the classical state by measuring a part of qubits. This operation destroys the 
quantum state and the information encoded in it. It is essential that he is unaware of the basis used for encoding 
when the qubits are passed to him. In view of the fact that the noncommutativity of X and Z prohibits their joint 
measurement, any measurement inevitably induces loss of information. For instance, suppose that Bob with M(< N) 
qubits memory employs the following simple strategy. When the qubits are sent, Bob keeps the first M qubits as they 
are and measures the remaining N — M qubits in the Z basis. This strategy allows Bob to obtain full information if 
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the basis used by Alice for encoding was Z. Conversely, it does not provide full information to Bob if the basis used 
by Alice was X, because he loses the information that was encoded in the first M qubits. Damgaard et al. Q has 
shown that dishonest Bob must have at least N/2 qubits quantum memory to benefit in this protocol. That is, the 
protocol works under the assumption of bounded quantum memory of size smaller than N/2. 

In this study, we inspect a toy two-party protocol that corresponds to the oblivious transfer protocol with dishonest 
Bob, but is not followed by privacy amplification. Consider the following problem. Assume that Alice encodes a 
random N bit sequence to a quantum state in the X or Z basis. How much information can Bob, who has a bounded 
quantum memory and an unbounded classical memory, retrieve after the basis is announced? By extracting part 
of a protocol in this manner, it is hoped that the understanding of the power of bounded quantum memory can be 
deepened. In addition, it may help improve the existing result, as was the case for the quantum key distribution 
protocol. We study the problem by employing the quantum Kolmogorov complexity as a measure of information, as 
defined by Vitanyi Q. In contrast to Shannon's theory, which treats only information of probabilistic sources, the 
Kolmogorov complexity is often called absolute information because it can assign information to individual objects. 
The key notion is algorithmic randomness. The complexity of an object is defined as the shortest description length 
in both classical Kolmogorov complexity and quantum Kolmogorov complexity given by Vitanyi. While the quantum 
Kolmogorov complexity is a natural concept for absolute information, it has been used in quantum information theory 
to develop only a few applications [H| developed in the quantum information theory. One of the purposes of this 
study is to demonstrate the usefulness of the quantum Kolmogorov complexity for analyzing protocols in this area. 

The next section contains a brief review of the quantum Kolmogorov complexity as defined by Vitanyi. In section 
IIII1 we introduce a toy two-party protocol and describe our main result based on it. The conclusion contains a 
discussion of the results. 



II. QUANTUM KOLMOGOROV COMPLEXITY BASED ON CLASSICAL DESCRIPTION 

The classical Kolmogorov complexity of a binary sequence is defined by the length of the shortest program, as 
proposed by Kolmogorov [l2j and Chaitin [l3j independently, for a one-way Turing machine to output the sequence. 
For instance, a binary sequence "000 . . . 00" has a short description such as "print "0" 10000 times," which therefore 
has a small Kolmogorov complexity. If a binary sequence has no pattern that yields any compressed description, the 
best way to describe it is to write it down naively. Such a sequence is called random. That is, a binary sequence is 
random if and only if its Kolmogorov complexity is as large as its own length. Although a specification of a Turing 
machine is required to define its value, the Kolmogorov complexity does not depend on the choice of a Turing machine 
except for a trivial constant. Moreover, the classical Kolmogorov complexity and its conditional version have various 
rational properties, as do Shannon entropy and conditional entropy. The Kolmogorov complexity plays a central 
role in field of algorithmic information theory whose applications extend to vast areas such as the foundation of 
mathematics, computation theory, and physics [lil Il5j. 

While it seems natural to define the corresponding complexity for quantum states, the quantum versions [l6l - [2fl | 
of the Kolmogorov complexity were only recently proposed. Among the several versions of the quantum Kolmogorov 
complexity, we employ the one that was defined by Vitanyi [gj. Vitanyi's definition based on the classical description 
length is suitable for quantum information-theoretic problems that normally handle classical inputs and outputs. In 
order to explain the definition precisely, a description of a one-way quantum Turing machine is needed. A one-way 
quantum Turing machine consists of four tapes and an internal control. (See [9] for more details.) Each tape is a 
one-way infinite qubit (quantum bit) chain and has a corresponding head on it. One of the tapes works as the input 
tape and is read-only from left-to-right. A program is given on this tape as an initial condition. The second tape 
functions as the work tape. The work tape is initially set to be for all the cells. The head on this tape can read and 
write a cell, and can move in both directions. The third tape is called an auxiliary tape. One can put an additional 
input on this tape. The additional input is written to the left-most qubits and can be a quantum state or a classical 
state. This input is needed when one deals with the conditional Kolmogorov complexity. The fourth tape works as 
the output tape. It is assumed that after halting the state over this tape will not be changed. The internal control is 
a quantum system described by a finite dimensional Hilbert space that has two special orthogonal vectors |<7o) (initial 
state) and \qf) (halting state). After each step one makes a measurement of a coarse grained observable on the internal 
control {\qf)(qj:\,l — \qf){qf\} to know if the computation halts [2l| . A computation halts at time t if and only if 
the probability to observe g/ at time £ is 1, and at any time t' < t the probability to observe qf is zero (see [22H25| 
for relevant discussions). By using this one-way quantum Turing machine, Vitanyi defined the quantum Kolmogorov 
complexity as the length of the shortest description of a quantum state. That is, the programs of quantum Turing 
machine are restricted to classical ones, while the auxiliary inputs can be quantum states. We write U(p,y) — \x) if 
and only if a quantum Turing machine U with a classical program p and an auxiliary (classical or quantum) input y 
halts and outputs \x). The following is the precise description of Vitanyi's definition. 
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Definition 1 The (self-delimiting) quantum Kolmogorov complexity of a pure state \x) with respect to a one-way 
quantum Turing machine U with y (possibly a quantum state) as conditional input given for free is 

K v (\x), | y) := min{Z(p) + [-log \{z\x)\ 2 ] : U(p,y) = \z)}, 
where l(p) is the length of a classical program p, and \a~\ is the smallest integer larger than a. 

The one-wayness of the quantum Turing machine ensures that the halting programs compose a prefix free set. Because 
of this, the length l(p) is defined consistently. The term |~— log |(z|a;}| 2 ] represents how insufficiently an output \z) 
approximates the desired output \x). This additional term has a natural interpretation using the Shannon- Fano code. 
Vitanyi has shown the following invariance theorem, which is very important. 

Theorem 1 Q/ There is a universal quantum Turing machine U , such that for all machines Q, there is a constant 
cq, such that for all quantum states \x) and all auxiliary inputs y we have: 

Ku{\x)\ y)<K Q {\x)\ y) + c Q . 

Thus the value of quantum Kolmogorov complexity does not depend on the choice of a quantum Turing machine if 
one neglects the unimportant constant term cq. Thanks to this theorem, one often writes K instead of Kjj. Moreover, 
the following theorem is crucial for our discussion. 

Theorem 2 Jji] On classical objects (that is, finite binary strings that are all directly computable) the quantum Kol- 
mogorov complexity coincides up to a fixed additional constant with the self- delimiting Kolmogorov complexity. That 
is, there exists a constant c such that for any classical binary sequence \x) , 

min{Z(g) : U(q,y) = \x)} > K{\x)\ y) > mm{l(q) : U{q,y) = \x)} - c 
g q 

holds. 

According to this theorem, for classical objects it essentially suffices to treat only programs that exactly output the 
object. 

III. FORMULATION AND RESULTS 

In order to discuss the power of the bounded quantum memory, we use a toy two-party protocol. Suppose that there 
exist two players Alice and Bob. Alice encodes a message in qubits with one of the bases X or Z, and sends them 
to Bob. The precise formulation is as follows. Alice chooses probabilistically [26] an TV-bit message x G {0, 1}^. She 
also chooses a basis X or Z for its encoding. We write the standard basis of a qubit as {|0}, |1}}, which are eigenstates 
of Z. Its conjugate basis is written as {|0), |1)}, which are eigenstates of X and are defined as |0) := -^|(|0) + |1)) 

and |1) :— ^(|0) — |1)). She prepares a quantum state of N qubits described by a Hilbert space Ha as follows. If 

her choice of basis is X, she encodes her message x = x\xi ■ ■ ■ xn S {0, 1}^ as \x) := \x~[) ® \~x~2) (g> • • ■ ® \xW) € Ha- 
Conversely, if her choice of basis is Z, she prepares \x) :— \xi) <X> \x 2 ) <8> • • • <8> \xn) S Ha- We define X x :~ \x)(x\ for 
each x € {0, 1}^ and Z z :— \z)(z\ for each z £ {0, 1}^. Bob, who has a bounded quantum memory and an unbounded 
classical memory, tries estimating the message after the basis is disclosed by Alice. There may exist some different 
formulations of the quantum bounded memory. For instance, one of the possible definitions would be such that Bob 
has many qubits that decohere in an uncontrollable way except for some M qubits. On the other hand, the following 
definition employed in this paper gives Bob the ability to control the system. Bob has an arbitrarily large system and 
he makes it interact with the qubits sent from Alice. The whole system that Bob possesses after the interaction is 
divided into two parts as H. m ® fC- The first part is the quantum memory that consists of M qubits. The second part 
is called an auxiliary part whose size can be arbitrarily large. Because Bob cannot keep the quantum coherence of the 
auxiliary part, he makes a measurement of an observable on it before the basis is announced by Alice. Let us denote 
the observable by C = {C^}, which forms a positive-operator-valued measure (POVM) on JC. The measurement 
result is stored in a classical memory whose size can be arbitrarily large. For as long as he needs, Bob can keep the 
quantum state on the quantum memory. He estimates the message encoded by Alice by using the quantum state in 
the quantum memory, the classical data in the classical memory and the basis disclosed by Alice. The whole process 
can be written as follows. The interaction between the qubits sent by Alice and Bob's apparatus is described by a 
completely positive map (CP-map), 



A : E(W A ) -> Z{H m ® K), 
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where denotes a set of all density operators on H. For instance, if Alice uses the basis Z for encoding message 

z, the state after the interaction becomes A(|z)(z|). Suppose that Bob obtained £ as an outcome. The quantum state 
kept in the quantum memory depends on Z, z, and £, and is denoted by p^t £ £(% m ), which can be calculated as 
an a-posteriori state 27). We treat the quantum Kolmogorov complexity K(z\pf Z) as a measure to characterize 



Bob's estimation |28j. That is, if Bob can estimate z exactly only from what he actually has, K(z\pf Z) = 0(1) 
holds. Otherwise, the quantum Kolmogorov complexity becomes nontrivial. Similarly, when Alice uses the basis X 
for encoding message x, and Bob obtains £ as an outcome of the measurement on the auxiliary system, we denote the 
quantum state in the quantum memory by p*^ £ T,(J-L m ). K(x\p^, £, X) characterizes Bob's ability to estimate the 
message x [28}. 

When M > N holds, Bob can recover the message perfectly by simply keeping the quantum states sent by Alice. 
We study how well Bob can recover the message when M < N is satisfied. 

In the following theorem, we study asymptotic behavior with respect to increasing N. For each N, the size of 
Bob's quantum memory M, which may depend on N, is bounded as M < qN for some q (0 < q < 1). For each N, 
P(x\£n, X) denotes a posterior probability of a message x £ {0, 1}^ when Alice used the basis X and Bob obtained 
outcome £at. Similarly, P(z\£n, Z) denotes a posterior probability of a message z £ {0, 1}^ when Alice used the basis 
Z and Bob obtained £jv- 

Theorem 3 Let us consider a family of protocols indexed by the number of qubits N . Assume that for each N the 
size of Bob's quantum memory M, which may depend on N , is bounded as M < qN for some q (0 < q < 1). For any 
px and pz satisfying q + px +Pz < 1, there exists Co > and e > such that for any 

P({x\K(x\p^ N ^ N ,X)<pxN}\^ N ,X) + P({z\K(z\pl iN ,C N ,Z)<p z N}\^ N ,Z) <1 + C 2~' N 

holds for a sufficiently large N, where P({x\K{x\p^ N , £ N , X) < p x N}\£_ Nl X) := J^x {x1p *^' £n ' X) - pxN P( x \£ n , X) 
and P({z\K(z\p^ N ^ N , Z) < p z N}\^ N , Z) := £)f {z ^' iN ' Z) ^ pzN Z ). 

The above theorem shows that there is a non-trivial trade-off relation between P({x\K(x\p^ N , £jv, X) < pxN}\£x, X) 
and P({z\ K(z\pZ £ N , £n, Z) < pzN}\£x, Z) when q +px +Pz < 1 holds. In particular, for sufficiently large N, if one 
of them is close to 1, the other becomes exponentially small. In other words, as there is a pair px and pz satisfying 
q + Px + Pz < 1 for any q < 1, there is a nontrivial effect of the bounded quantum memory for any q < 1. 
The above theorem is derived from the following lemma. 

Lemma 1 Let us consider a protocol for a fixed N and M . For any integers lx,lz > 0, it holds: 

P({x\K(x\p^^,X) <lxm,X) + P({z\K(z\pl i ^,Z) <l z m,Z) < 1 + 2 s + c , 

where P({x\K(x\p^,^X) < l x }\H,X) := £f W^*)^ - P(x\^X), P{{z\K(z\p z z £ ,£,Z) < l z }%Z) := 

and c is a constant depending on the choice of a quantum Turing machine. (Note that this 
inequality is non-trivial only for l x+iz+M-N _|_ c <- q j 

Proof: 

We fix a universal quantum Turing machine U and discuss the quantum Kolmogorov complexity with respect to 
it. We fix £ throughout the proof. Let us consider Ku{z\p z ^,^, Z) nrs t- Thanks to theorem^ it suffices to consider 
only programs that exactly output the message z because the message is a classical object. That is, we regard 

Kc,u(z\Pz, Z) := min l(q), 

q:U(q,pl v t,Z)=\z) 

which satisfies K Ct u{z\p^^ £, Z) > K(j(z\p z Z) > K Ct u{z\p Z e,^, Z) — c! for some constant d . 

Let us denote by Tj C {0, 1}* a set of all programs that output z with auxiliary inputs p% £, (, and Z. That is, 
Tf = {t£ {0, l}*\U(t, p z >£ , £, Z) = z] holds. An equation K c>u (z\p z £ , £, Z) = min teT « l(t) follows. Although different 
programs may have different halting times, from the lemma proved by Miiller (Lemma 2.3.4. in _2Cj ), we note that 
there exists a completely positive map (CP-map) Tu,$,z ■ E(Hm ® Hi) — > S('Ho) satisfying for any t £ Tj 

TutAplti ® 1*> <*D = \z){z\, 
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where Hi is a Hilbert space for programs, and Ho = <E) N C2 is a Hilbert space for outputs. From this theorem, we 
obtain an important observation. If n TJ, ^ holds for some z ^ z', and pf, * are perfectly distinguishable. 
In fact, because a CP-map does not increase the distinguishability of states, the relationships for t 6 Tf n T|, 

r^,z(pf,g®|*)<*|) = |2:)<«| 

r^,z(pf^<8|t)<t|) = |« / ><« , | 

and their distinguishability on the right-hand sides imply the distinguishability of pP+ and p^, t. For each i G {0, 1}*, 

we define C| C {0, 1}^ as = {z\t G T z }. That is, z G C| is a message that can be reconstructed by giving a program 
t to the Turing machine U with auxiliary inputs pf £, £ and Z. Owing to the distinguishability between p^j and p^ ^, 

for z, z' G Cj , there exists a family of projection operators {E^} zeC z on H m satisfying for any z, z' G C|, 



2GC, £ 



< 1 



tr(p^) = <S 



Because the memory is bounded as dim H m < 2 



M 



< 2 



M 



holds. Because we are interested in minimum length programs, we define T)\ :— {z\t — argmin sgT £Z(s)}, which is a 
set of all messages that have t as the minimum length program for reconstruction. T)\ C C\ holds. It is still possible 
that V\ n V% ^ 0. That is, there may be a message z whose shortest programs are not unique. In such a case, we 
choose one of these programs to avoid counting doubly. For instance, this can be done by introducing a total order 
< in all the programs {0, 1}*, and by defining E\ = {z\z G v\, z £ T)\, for all t' < t with l(t) = l(t')}. As this £f is a 
subset of Cf, for any z, z' G £f 



hold. The cardinality of £f satisfies 



£ ^ 1 

zee* 



(1) 
(2) 



tr(p^) 



t,6\ _ 



< 2 



(3) 



Similarly, we treat Kjj{x\p^, £, X). We can introduce S| G {0, 1}* as a set of all programs that output x with 
auxiliary inputs p* £, and X. if C)i 7(a;|p^,, £, X) = min ses5 Z(s) holds. We can define := {x\s G S|} for each s 
and introduce a family of projection operators {-^x } x p^ on ^ m sa tisfies 

for each x, x' G ,7/ and so on. 0| := {x|s = argmin tgS {/(t)} and J 7 ! = {z|z G Gj,z £ Q s i for all s' < s with Z(s) = 
i(s')}, are also defined. An inequality for the cardinality, 



l-^ll < I J/ 1 <2 



,1/ 



(4) 



also holds. We consider a family of projection operators {^""IzgjF 5 - 

Let us analyze the protocol. Instead of the original protocol, we treat an entanglement-based protocol (E91-like 
protocol [1^]), which is equivalent to the original one. It runs as follows. Alice prepares N pairs of qubits. She 
prepares each pair in the EPR state, \<p) := ^(|0) ® |0) + |1) <& |1)). Therefore, the whole state can be written as 
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\(j> N ) : = \(f>) o |0) o • ■ ■ (g) \cf)) (N times) in a Hilbert space U A > ® Ha, where H A > ~Ua^ ® n C 2 . Alice sends the 
qubits described by %b to Bob. Bob makes the system T-La interact with his apparatus as 

A : E(Ha) -> ^{Um ® K). 

Bob measures his auxiliary system K with POVM C = {C^}. When Bob has obtained £, we denote by 0£ the 
a-posteriori state over Ha 1 ® H m - Alice measures her system Ha' with one of the bases X or Z to obtain a 
message. It can be shown that when Bob's obtained outcome was £ and Alice chose X and obtained ir, the state on 
the quantum memory T-L m is p^e- Similarly, when Bob's obtained outcome was £ and Alice chose Z and obtained z, 
the state on the quantum memory H m is ^. 

Hereafter we treat the state 0£ over Ha' ® % m - Let us define a projection operator for each t E {0, 1}*, Pf := 
E 2e£ « ^ ® and for each s e {0, 1}*, Qf := ® 5 - For any integers l' x ,l' z > 0, we introduce 

projection operators, pJ :— J^t^* ^ an d Of' : — Es x • Their expectation values with respect to 0{ can 
be written as: 

tr(0 € P«) = P({z\K C}U (z\pl ( ,Z,Z)<l' z }\Z,Z) (5) 
tr(9 c Q^) - P({x\K c ,u{x\pZ tV t,X)<l' x }\t,X). (6) 

Our purpose is to find a trade-off inequality between ([5]) and (J6)). It is obtained by the use of the uncertainty 
relation, which is one of the most important relation characterizing quantum mechanics. Among the various forms of 
uncertainty relations, we employ the Landau-Pollak uncertainty relation [33,|3l|. According to the generalized form 
given in [31|, for an arbitrary number of projections {A{\ 1 it holds that for any quantum state p, 

5>( P A i )<l + (^jj^A 

We apply this inequality for the state 8{ and a family of positive operators {Pt,Q s } (l(t) < l' Z) l(s) < l' x ). Because 
P t P t , = Q a Q s , = holds for t ^ t' and s ^ s' thanks to £f n f| = J| n jf, = 0, we obtain: 

l(t)<l' z l(s)<l' x \ 1 1 




tr(&sM ) + tr(9 c Qf ) < 1 + 2 ]T 2 



f " 2 



The term ||Q|Pj || on the right-hand side is computed as follows. As the operator norm ||QfP t || is written as 
||Q|P t || = sup|^\.||^\|i =1 HQfPj 1^)11, we need to bound ||Q|P t |^)|| for any normalized vector j*). We consider: 



Spf|*}|| = <*|jfQ|jf|*)Va. (7) 
As Qi = J2 x <efI X * ® F x^ ^ E^jpf X x ®1m holds, (O can be bounded as 

(*|Q*ifQf|¥> 1/a < [EE ^(*|(^®p«)(x :c ®1m)(^®^)|*} > ) 

\zesl x£Tl z'es* J 

\ 1/2 

where we have used (TTJ). The right-hand side can be further deformed by introducing the a-posteriori state [I3| A 4 *'^ 
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1/2 i \ 1/2 

£ £ (¥|Z,X X £, ® £<' e |#) J = I E E tr(^Z z X x Z z )(V\l B ® 

1/2 



< 



E E ^(*iib®^i*)J 



1/2 



M-N 



where we have used a relation |tr(^ e Z z X x Z 2 )| < \\Z Z X X Z Z \\ = ^, © and Q. Thus we obtain ||QfP t S || < 2 
Because \{t\l(t) < l' z }\ < 2 l 'z +1 and \{s\l{s) < l' x }\ < 2 l '* +1 hold, we obtain 



M-N 
— 2 — 



1 V + 1 7+ M - JV + 3 



tr(6 ? Pj) + tr(6 ? Q^) < 1 + 2" 
Taking into account the relation between i^ C) [/ and Kjj we finally obtain: 

P({x|K(:e|^ c ,£,A) < l x }%X) + P{{z\K(z\p z z>6 ,fi,Z) < l z }%Z) <l + T 

where c is a constant that depends on the choice of the quantum Turing machine. Q.E.D. 

Proof of theorem [3} Apply lemma [1] with lx — pxN, lz — pzN and M = qN. As c does not depend on N, we 
define C* := 2 C . If we define e := Lzig±£*±M2 ; we obtain the theorem. Q.E.D. 

In addition, the following corollary immediately follows: 

Corollary 1 Let us consider a protocol with fixed N . For any memory size M > and any £, it holds 

max K(x\p^ f , £, X) + max K(z\p z f , f,Z)>N — M + c. 

Proof: From P({x|iv £, A) < max, Jf(a:|p^,£, X)}\£, X) = 1, P({ 2 |^|p^, £, Z) < 

max z K(z\p^^ £, Z)}|£, Z) = 1, and the lemma [TJ the claim immediately follows. (For M = 0, it also holds.) 
Q.E.D. 

This corollary is regarded as a kind of generalizations of Heisenberg's uncertainty principle [32]. In fact, the case 
M = corresponds to the standard measurement scenario without a quantum memory. It implies that there is no 
observable that works as the joint measurement of X and Z. 



IV. DISCUSSION 



In this study, the power of the bounded quantum memory in simple information processing was examined. A toy 
two-party protocol was employed in which Bob, by using a bounded quantum memory and an unbounded classical 
memory, estimated messages encoded by Alice in one of the bases X or Z. His ability to guess the message was 
characterized by the quantum Kolmogorov complexity. Our theorem provided a nontrivial effect of the memory 
boundedness. In addition, as a corollary, we obtained a generalization of the uncertainty principle with the quantum 
memory. As a future problem, it would be natural to apply the present study to the oblivious transfer. It should be 
noted that in Q, non-trivial result was obtained only for the quantum memory smaller than N/2 in the context of 
oblivious transfer, whereas our result indicates that there may be a non-trivial effect also for the quantum memory 
for which the size is qN for some q < 1. To investigate the complete protocol, we need to treat privacy amplification 
by using the Kolmogorov complexity. In addition, by combining the present result with the information-disturbance 
theorem [lip in quantum key distribution, our theorem may play a role in estimating the threat of an eavesdropper 
who has a bounded quantum memory. We hope to investigate these problems in the future. 
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